58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.478 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-0876 | HIGH 10.0 | microsoft ie Buffer overflow in Internet Explorer 4.0 via EMBED tag. | 5.7% | — |
| CVE-2019-0988 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. | 5.7% | — |
| CVE-2017-8661 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsof | 5.7% | — |
| CVE-2018-0819 | MED 6.5 | microsoft office Microsoft Office 2016 for Mac allows an attacker to send a specially crafted email attachment to a user in an attempt to launch a social engineering attack, such as phishing, due to how Outlook for Mac displays encoded email addresses, aka "Spoofing Vulnerabil | 5.7% | — |
| CVE-2019-0820 | HIGH 7.5 | microsoft .net_core A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981. | 5.7% | — |
| CVE-2018-8310 | HIGH 7.5 | microsoft office A tampering vulnerability exists when Microsoft Outlook does not properly handle specific attachment types when rendering HTML emails, aka "Microsoft Office Tampering Vulnerability." This affects Microsoft Word, Microsoft Office. | 5.7% | — |
| CVE-2023-33131 | HIGH 8.8 | microsoft office Microsoft Outlook Remote Code Execution Vulnerability | 5.7% | — |
| CVE-2019-0906 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vu | 5.7% | — |
| CVE-2014-0296 | MED 5.1 | microsoft windows_7 The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly encrypt sessions, which makes it easier for man-in-the-middle attackers to obtain sensitive information b | 5.7% | — |
| CVE-2017-8651 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows Server 2008 SP2 and Windows Server 2012 allows an attacker to execute arbitrary code in the context of the current user due to Internet Explorer improperly accessing objects in memory, aka "Internet Explorer Memory Corrup | 5.7% | — |
| CVE-2000-0416 | MED 5.0 | microsoft windows_2000 NTMail 5.x allows network users to bypass the NTMail proxy restrictions by redirecting their requests to NTMail's web configuration server. | 5.7% | — |
| CVE-2022-23267 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5.7% | — |
| CVE-2021-40480 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 5.7% | — |
| CVE-2001-0332 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain usin | 5.7% | — |
| CVE-2022-29117 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5.7% | — |
| CVE-2017-8549 | HIGH 7.5 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Memory C | 5.7% | — |
| CVE-1999-0680 | MED 5.0 | microsoft terminal_server Windows NT Terminal Server performs extra work when a client opens a new connection but before it is authenticated, allowing for a denial of service. | 5.7% | — |
| CVE-2018-8517 | HIGH 7.5 | microsoft .net_framework A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4. | 5.7% | — |
| CVE-1999-1452 | LOW 2.1 | microsoft windows_nt GINA in Windows NT 4.0 allows attackers with physical access to display a portion of the clipboard of the user who has locked the workstation by pasting (CTRL-V) the contents into the username prompt. | 5.7% | — |
| CVE-2017-0185 | MED 5.8 | microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Server 2012 R2, or Windows Server 2016 host server fails to properly validate input from a privileged user on a gu | 5.7% | — |
| CVE-2017-8648 | MED 4.3 | microsoft windows_10 Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE | 5.7% | — |
| CVE-2017-8597 | MED 4.3 | microsoft windows_10 Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This | 5.7% | — |
| CVE-2001-0246 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka | 5.6% | — |
| CVE-2001-0047 | HIGH 7.5 | microsoft windows_nt The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities. | 5.6% | — |
| CVE-2020-1408 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'. | 5.6% | — |